Scope
This policy covers the Atlassian Marketplace apps published by KeulTech, Andreas Keul, including „Dependency Guard for Jira“.
Architecture and data handling
Our apps are built on Atlassian Forge and run entirely on Atlassian-operated infrastructure. They declare no outbound network access, operate no servers of our own, and use no third-party services or sub-processors. Customer data never leaves the Atlassian platform. Persistent data is limited to the Forge Storage API. Details are documented in our Privacy Policy.
Access control
KeulTech has no runtime access to customer data. There is no provider-operated database, log store, or administrative console holding customer data. Development and deployment access is limited to the sole proprietor’s own Atlassian account, which is protected by a unique password and two-factor authentication.
Permissions
Our apps request the minimum Atlassian scopes required to function, and these are declared in the app manifest and visible to administrators before installation. Where an app acts in a user-facing context, it performs API calls under the requesting user’s own identity, so existing permissions are enforced.
Reporting a vulnerability
Email info@keul.tech with „SECURITY“ in the subject line. Please include the affected app, a description of the issue, and steps to reproduce it.
- We acknowledge reports within one business day.
- We aim to provide an assessment within five business days.
- We will keep you informed until the issue is resolved, and will credit you if you wish.
Please do not publicly disclose a vulnerability before we have had a chance to address it. We will not pursue legal action against researchers who report issues in good faith and do not access, modify, or destroy customer data.
Patching
Security fixes are deployed as a new app version through the Atlassian Marketplace. Because our apps run on Forge, updates reach all installations without customer action.
Incident notification
If an incident affects customer data, we will notify affected customers and report the incident to Atlassian through the Marketplace partner incident process.